Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

CrowdStrike Falcon Certification Program CCFA-200b Question # 23 Topic 3 Discussion

CrowdStrike Falcon Certification Program CCFA-200b Question # 23 Topic 3 Discussion

CCFA-200b Exam Topic 3 Question 23 Discussion:
Question #: 23
Topic #: 3

Your leadership wants controls in place for immediate action on any OverWatch detections. What should you do to ensure the host is contained quickly and notifies the appropriate staff?


A.

Create a Fusion SOAR workflow using the OverWatch playbook to contain the host and email the SOC team


B.

Create a Fusion SOAR workflow to contain the host and email the OverWatch team


C.

Create a Fusion SOAR workflow to trigger on an OverWatch detection and set it to block the detection


D.

Create a Fusion SOAR workflow to create a detection for OverWatch and email the SOC team


Get Premium CCFA-200b Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.